CGRC Exam Question 51

Process of formally evaluating the degree of threat to an information system or enterprise and describing the nature of the threat.
Response:
  • CGRC Exam Question 52

    Which of the following describes residual risk as the risk remaining after risk mitigation has occurred? Response:
  • CGRC Exam Question 53

    A written plan for recovering one or more information systems at an alternate facility in response to a major hardware or software failure or destruction of facilities.
    Response:
  • CGRC Exam Question 54

    FIPS 199, Standards for Security Categorization of Federal Systems defines which 3 Security Categories? Response:
  • CGRC Exam Question 55

    What is included in a POA&M that is presented to the Approving Authority as part of the initial authorization package?
    Response: